Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue affects Mediawiki - CSS Extension: from 1.42.X before 1.42.2, from 1.41.X before 1.41.3, from 1.39.X before 1.39.9.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
1.42.x (semver) before 1.42.2
1.41.x (semver) before 1.41.3
1.39.x (semver) before 1.39.9
Credits
RhinosF1
BlankEclair
References
phabricator.wikimedia.org/T368628
phabricator.wikimedia.org/T369486
gerrit.wikimedia.org/...3d8d50fc978bdac58e2b312ee03324c1edc8
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.